id gog+




I tested this on the [Oauth2 playground](https://developers.google.com/oauthplayground/) and sent these scopes

>email openid profile Initial request : ```

```

Decoded Id token

``` ```

Response from Refresh of access token

``` ```

Decoded Id token

``` ```

The profile claims are missing from the id token in the response from a refresh token. The email scope should add the following scope to the claim ``` "email": "XXXX@gmail.com", ``` The profile scope should add the following scopes to the claim

``` ```

I am leaning towards this being a bug in the identity servers response as email is still there. Which to me implies that the scopes should be returned in the claim from the refresh token as well. I am not aware of anything in the rfc for open id saying that the id token response from a refresh token wouldnt include all of the original claims. #googleoauth #oauth2 #oauth #identityserver #openid #bug https://github.com/google/google-api-dotnet-client/issues/1141



Создан 06 янв 2018



  Комментарии       
Имя или Email


При указании email на него будут отправляться ответы
Как имя будет использована первая часть email до @
Сам email нигде не отображается!
Зарегистрируйтесь, чтобы писать под своим ником